Static | ZeroBOX

PE Compile Time

2068-07-30 20:28:13

PDB Path

FJHFFRR.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
\x16@X-\x16"oN 0x00002000 0x00006048 0x00006200 7.99316706915
.text 0x0000a000 0x0000a9d8 0x0000aa00 5.03253062404
.rsrc 0x00016000 0x00000596 0x00000600 4.07233613217
0x00018000 0x00000010 0x00000200 0.122275881259
.reloc 0x0001a000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000160a0 0x0000030c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000163ac 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x418000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
`.reloc
er&-Y3
^^f9_o
_t!w!U
pPQE^^E'=
CDi^>7
6hr5}ex"
c>+$NKV
2pvv ^
~5>W(.
Y`Qp<9dI
j _Fu6
T<y}[>
BgbdXV9U3
K![y@K
=(iN2s
ZCGqW8
5Bu!kk
*5q(i5
Y1v2|r
hp:N'm
0~h$ME
u!cJqq:
OAd#z/
ya,;#M
#goUN+q
7Y9YzS+
m?R+6?
OrY:TD
jinG?U
'8U$eh8Iz
{c<BSDd
h{-1V{
k{?w[a
[J>[8K
U.\:"G
dQiftH
OJe`<I
Kr8T3t
+u9@WL5
*D%4B#
]j3=Wi
^5T#r06gU
_~gOeT
_iGX
@IZ%&8
SeZ oM
UtDNZ f
B-%Z 3
4Z C5g
O9pa87
RSDSxSs#w!
FJHFFRR.pdb
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
oPC\IzrQ~I}EvE5j8SPAr;yW,
O+Km"oJ{pDD>LF67x\};=8e:/
<>9__6_0
'Q)96Ogm+(h>78_GXNEYn?!21
Task`1
AsyncTaskMethodBuilder`1
TaskAwaiter`1
UInt32
ToInt32
^<'\{iD{Re@n4SG2N)VBrL`"3
ToInt16
get_UTF8
e\q{a+@(^~ZFIv97-:StV+4a8
<Module>
CreateProcessA
GetHINSTANCE
get_ASCII
System.IO
FJHFFRR
TripleDES
set_IV
mscorlib
DownloadStringTaskAsync
ResumeThread
get_CurrentThread
thread
get_IsAttached
AwaitUnsafeOnCompleted
get_IsCompleted
Synchronized
set_IsBackground
GetMethod
distance
CreateInstance
set_Mode
PaddingMode
CryptoStreamMode
CipherMode
get_Message
Invoke
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
Console
get_Module
get_Name
get_FullyQualifiedName
get_FullName
DateTime
WriteLine
Combine
IAsyncStateMachine
SetStateMachine
stateMachine
ValueType
SecurityProtocolType
GetElementType
MethodBase
ApplicationSettingsBase
Dispose
Reverse
Create
EditorBrowsableState
posState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AsyncStateMachineAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
get_IsAlive
add_AssemblyResolve
FJHFFRR.exe
inSize
outSize
dwSize
windowSize
dictionarySize
SizeOf
System.Threading
set_Padding
Encoding
IsLogging
System.Runtime.Versioning
FromBase64String
ToBase64String
GetString
get_Length
FlushFinalBlock
get_Task
Marshal
System.ComponentModel
kernel32.dll
ntdll.dll
set_SecurityProtocol
inStream
CryptoStream
outStream
MemoryStream
stream
System
SymmetricAlgorithm
ICryptoTransform
IsLittleEndian
MIJFzBeQxeWaYOFOnpVGTFELMHgn
AppDomain
get_CurrentDomain
System.Configuration
System.Globalization
Action
ZwUnmapViewOfSection
System.Reflection
SetException
Intern
MethodInfo
CultureInfo
AsyncTaskMethodBuilder
sender
rangeDecoder
Buffer
ResourceManager
ServicePointManager
Debugger
ResolveEventHandler
System.CodeDom.Compiler
TaskAwaiter
GetAwaiter
BitConverter
.cctor
CreateDecryptor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
O\+Km"oJ{pDD>LF67x\\};=8e:/.resources
DebuggingModes
FJHFFRR.Properties
properties
numPosStates
GetBytes
Settings
ResolveEventArgs
get_Ticks
System.Threading.Tasks
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
lpAddress
numTotalBits
numPosBits
numPrevBits
Format
Object
lpflOldProtect
VirtualProtect
flNewProtect
System.Net
op_Explicit
Default
GetResult
SetResult
WebClient
RuntimeEnvironment
get_TickCount
ParameterizedThreadStart
Convert
FailFast
MoveNext
System.Text
GetThreadContext
SetThreadContext
get_Now
VirtualAllocEx
startIndex
InitializeArray
ToArray
set_Key
System.Security.Cryptography
get_Assembly
GetCallingAssembly
GetExecutingAssembly
BlockCopy
ReadProcessMemory
WriteProcessMemory
GetRuntimeDirectory
op_Equality
Confuser.Core 1.6.0+447341964f
WrapNonExceptionThrows
FJHFFRR
Copyright
2025
$a6b3a713-cf13-4d65-bd95-1f1d6c482055
1.0.0.0
.NETFramework,Version=v4.5.2
FrameworkDisplayName
.NET Framework 4.5.2
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
5'Q)96Ogm\+(h>78_GXNEYn?!21+^<'\\{iD{Re@n4SG2N)VBrL`"3
8e\\q{a\+@(^~ZFIv97-:StV\+4a8+oPC\\IzrQ~I}EvE5j8SPAr;yW\,
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FJHFFRR
FileVersion
1.0.0.0
InternalName
FJHFFRR.exe
LegalCopyright
Copyright
2025
LegalTrademarks
OriginalFilename
FJHFFRR.exe
ProductName
FJHFFRR
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Generic
Skyhigh BehavesLike.Win32.Generic.lh
ALYac Gen:Variant.MSILHeracles.222889
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:MSIL/MalwareX.350ca252
K7GW Trojan-Downloader ( 005c66201 )
K7AntiVirus Trojan-Downloader ( 005c66201 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.RYW
APEX Malicious
Avast Win32:MalwareX-gen [Drp]
Cynet Clean
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.MSILHeracles.222889
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Agent.72192.ZT
MicroWorld-eScan Gen:Variant.MSILHeracles.222889
Tencent Msil.Trojan-Downloader.Ader.Ychl
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.srrdv
DrWeb Clean
VIPRE Gen:Variant.MSILHeracles.222889
TrendMicro TROJ_GEN.R002C0XDU25
McAfeeD Real Protect-LS!30A67726C448
Trapmine malicious.high.ml.score
CTX exe.trojan.msil
Emsisoft Gen:Variant.MSILHeracles.222889 (B)
Ikarus Trojan-Downloader.MSIL.Agent
GData Gen:Variant.MSILHeracles.222889
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Troj.C.gen!Eldorado
Avira TR/Dldr.Agent.srrdv
Antiy-AVL Trojan/MSIL.Kryptik
Kingsoft malware.kb.c.995
Gridinsoft Trojan.Heur!.03013281
Xcitium Clean
Arcabit Trojan.MSILHeracles.D366A9
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.Injection.C5758223
Acronis Clean
McAfee Artemis!30A67726C448
TACHYON Clean
VBA32 CIL.HeapOverride.Heur
Malwarebytes Trojan.Downloader.MSIL
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0XDU25
Rising Downloader.Agent!8.B23 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Agent.RYW!tr.dldr
AVG Win32:MalwareX-gen [Drp]
DeepInstinct MALICIOUS
alibabacloud Trojan[dropper]:MSIL/Phonzy.A9nj
No IRMA results available.